CVE-2008-3356
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
05/08/2008
Last modified:
09/04/2025
Description
verifydb in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and other Unix platforms sets the ownership or permissions of an iivdb.log file without verifying that it is the application's own log file, which allows local users to overwrite arbitrary files by creating a symlink with an iivdb.log filename.
Impact
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:ingres:ingres:2.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:ingres:ingres:2006:9.0.1:*:*:*:*:*:* | ||
cpe:2.3:a:ingres:ingres:2006:9.0.4:*:*:*:*:*:* | ||
cpe:2.3:a:ingres:ingres:2006:release_1:*:*:*:*:*:* | ||
cpe:2.3:a:ingres:ingres:2006:release_2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=731
- http://secunia.com/advisories/31357
- http://secunia.com/advisories/31398
- http://securitytracker.com/id?1020613=
- http://www.ingres.com/support/security-alert-080108.php
- http://www.securityfocus.com/archive/1/495177/100/0/threaded
- http://www.securityfocus.com/bid/30512
- http://www.vupen.com/english/advisories/2008/2292
- http://www.vupen.com/english/advisories/2008/2313
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44177
- https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=181989
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=731
- http://secunia.com/advisories/31357
- http://secunia.com/advisories/31398
- http://securitytracker.com/id?1020613=
- http://www.ingres.com/support/security-alert-080108.php
- http://www.securityfocus.com/archive/1/495177/100/0/threaded
- http://www.securityfocus.com/bid/30512
- http://www.vupen.com/english/advisories/2008/2292
- http://www.vupen.com/english/advisories/2008/2313
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44177
- https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=181989